Attack countermeasures, attack countermeasures

The attack countermeasure system addresses the issue of temporary functional limitations in cyberattack responses by implementing two-stage countermeasures based on attack path and damage location, effectively reducing the impact of cyberattacks on vehicles.

JP2026049579APending Publication Date: 2026-03-18DENSO CORP +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-06
Publication Date
2026-03-18

AI Technical Summary

Technical Problem

Existing cyberattack countermeasures on vehicles, such as those described in Patent Document 1, may cause temporary functional limitations due to the time required to implement security measures, and there is a need for measures that minimize the impact of cyberattacks on vehicles.

Method used

An attack countermeasure system with a first and second action execution device that determines and executes measures based on the attack path and damaged location, respectively, to minimize the impact of cyberattacks on vehicles.

Benefits of technology

The system reduces the impact of cyberattacks by implementing targeted countermeasures in two stages, minimizing functional limitations and ensuring rapid response to detected threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026049579000001_ABST
    Figure 2026049579000001_ABST
Patent Text Reader

Abstract

This invention provides an attack countermeasure system and a method for implementing it that take steps to counter an attack when a vehicle is subjected to a cyberattack. [Solution] An attack countermeasure system 1 having a first action execution device 300 and a second action execution device 350 for executing measures against an attack on a mobile body, wherein the first action execution device includes a first instruction information acquisition unit that acquires first instruction information instructing to execute a first measure which is a measure to prevent the effects caused by the attack, which is determined based on the attack path of the attack on the mobile body, and a first action execution unit that executes the first measure based on the first instruction information, and the second action execution device includes a second instruction information acquisition unit that acquires second instruction information instructing to execute a second measure which is determined based on the damaged area that has been hit by the attack, which is a second measure to the damaged area, and a second action execution unit that executes the second measure after the first measure has been executed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , , , , , , , ,

[0005] , , , , ,

[0001] The present invention mainly relates to an attack countermeasure system that detects a cyber attack in a moving body and takes measures against the attack when a cyber attack is performed on a moving body such as an automobile, and a method executed by the system.

Background Art

[0002] In recent years, technologies for performing driving assistance and automatic driving control, such as V2X including vehicle-to-vehicle communication and vehicle-to-roadside communication, have attracted attention. Along with this, vehicles have come to have a communication function, and so-called vehicle connectivity has been progressing. As a result, the possibility that a vehicle is subjected to a cyber attack such as unauthorized access has been increasing. Since there is a possibility of losing control of the vehicle due to a cyber attack, stronger defensive means against cyber attacks are required.

[0003] Here, regarding cyber attacks on vehicles, for example, in Patent Document 1, a device is disclosed that detects an incident based on vehicle logs, identifies a device having a vulnerability related to the incident within a network, and performs a temporary measure such as partially stopping the function on the identified device.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

Summary of the Invention

Problems to be Solved by the Invention

[0005] Here, as a result of detailed examination, the present inventor has found the following problems. Patent Document 1 states that the temporary measures will be lifted once it is confirmed that security measures for the vulnerability have been implemented. However, it can take time for security measures for the vulnerability to be completed. Therefore, if the scope of the temporary measures is wide, continuing the temporary measures until the security measures are completed may result in consequences such as limitations on the vehicle's functions.

[0006] Therefore, the present invention aims to implement measures that ultimately minimize the impact on vehicles from cyberattacks, and to perform cyberattack detection processing that makes such measures possible. [Means for solving the problem]

[0007] The attack countermeasure system of this disclosure is an attack countermeasure system (1) having a first action execution device (300) and a second action execution device (350) for executing measures against an attack on a mobile body, wherein the first action execution device includes a first instruction information acquisition unit (301) that acquires first instruction information instructing to execute the first action, which is a measure to prevent the effects caused by the attack, which is determined based on the attack path of the attack on the mobile body, and a first action execution unit (302) that executes the first action based on the first instruction information, and the second action execution device includes a second instruction information acquisition unit (351) that acquires second instruction information instructing to execute the second action, which is a measure to be taken against the damaged location, which is determined based on the damaged location affected by the attack, and a second action execution unit (352) that executes the second action based on the second instruction information after the first action has been executed.

[0008] The numbers in parentheses attached to the claims and the constituent elements of the invention described in this section indicate the correspondence between the present invention and the embodiments described later, and are not intended to limit the present invention. [Effects of the Invention]

[0009] With the configuration described above, the attack countermeasure system of this disclosure can determine attack countermeasures corresponding to the attack detection process at each stage by performing attack detection processing in two stages when a vehicle is subjected to a cyberattack. Furthermore, by implementing countermeasures against attacks on the vehicle in accordance with the attack detection process at each stage, the impact of attacks and countermeasures on the vehicle can be reduced. [Brief explanation of the drawing]

[0010] [Figure 1] Block diagram illustrating the overall configuration of the attack countermeasure system 1 in each embodiment. [Figure 2] Diagram illustrating the arrangement of each device constituting the attack countermeasure system 1 in each embodiment. [Figure 3] Block diagram illustrating an example configuration of the electronic control system in each embodiment. [Figure 4] Block diagram illustrating the configuration example of the electronic control unit for each embodiment. [Figure 5] Block diagram illustrating an example configuration of the first attack detection device of Embodiment 1. [Figure 6] Diagram illustrating the attack determination table of Embodiment 1 [Figure 7] Block diagram illustrating an example configuration of the first measure determination device of Embodiment 1. [Figure 8] This diagram illustrates the reference information stored in the reference information storage unit of the first measure determination device of Embodiment 1. [Figure 9] Block diagram illustrating an example configuration of the first action execution device of Embodiment 1. [Figure 10] Block diagram illustrating an example configuration of the second attack detection device of Embodiment 1. [Figure 11] Block diagram illustrating an example configuration of the second measure determination device of Embodiment 1. [Figure 12] This diagram illustrates the reference information stored in the reference information storage unit of the second measure determination device of Embodiment 1. [Figure 13] Block diagram illustrating an example configuration of the second action execution device of Embodiment 1. [Figure 14] Block diagram for explaining the operation of the attack countermeasure system of Embodiment 1

Mode for Carrying Out the Invention

[0011] Hereinafter, embodiments of the present invention will be described with reference to the drawings.

[0012] The present invention means the invention described in the claims or the section of means for solving the problems, and is not limited to the following embodiments. Also, at least the terms in parentheses mean the terms described in the claims or the section of means for solving the problems, and are not limited to the following embodiments either. [[ID=IS]]

[0013] The configurations and methods described in the dependent claims of the claims are arbitrary configurations and methods in the invention described in the independent claim of the claims. The configurations and methods of the embodiments corresponding to the configurations and methods described in the dependent claims, as well as the configurations and methods described only in the embodiments without being described in the claims, are arbitrary configurations and methods in the present invention. The configurations and methods described in the embodiments when the description of the claims is broader than the description of the embodiments are also arbitrary configurations and methods in the present invention in the sense that they are examples of the configurations and methods of the present invention. In any case, by describing in the independent claim of the claims, it becomes the essential configuration and method of the present invention.

[0014] The effects described in the embodiments are the effects in the case of having the configuration of the embodiment as an example of the present invention, and are not necessarily the effects of the present invention.

[0015] When there are a plurality of embodiments, the configurations disclosed in each embodiment are not limited to each embodiment alone, and can be combined across embodiments. For example, the configuration disclosed in one embodiment may be combined with another embodiment. Also, the configurations disclosed in each of the plurality of embodiments may be collected and combined.

[0016] The problems described in the section on the problems that the invention aims to solve are not publicly known problems, but rather problems that the inventors have discovered independently, and together with the structure and method of the present invention, these facts affirm the inventive step of the invention.

[0017] 1. Configuration that serves as the basis for the embodiment (1) Overall configuration of the attack countermeasure system Referring to Figures 1 and 2, we will first describe the overall configuration showing the devices related to the attack countermeasure system 1 and their interrelationships.

[0018] As shown in Figure 1, the attack countermeasure system 1 includes a first attack detection device 100, a second attack detection device 150, a first action decision device 200, a second action decision device 250, a first action execution device 300, and a second action execution device 350. The first attack detection device 100 and the second attack detection device 150 are devices that detect attacks on vehicles, which are "moving objects." The first action decision device 200 and the second action decision device 250 are devices that decide on the action to take in response to the attack. The first action execution device 300 and the second action execution device 350 are devices that execute the action to take in response to the attack. The specific configuration of each device will be described later.

[0019] Here, "moving object" refers to any object that can move, regardless of its speed. It also includes objects that are stationary. Examples include, but are not limited to, automobiles, motorcycles, bicycles, pedestrians, ships, aircraft, and items carried on them.

[0020] Each of the devices shown in Figure 1 may be provided as separate devices, or they may be provided as a single device connected by an internal bus.

[0021] Figure 2 is a diagram illustrating the arrangement of each device constituting the attack countermeasure system 1. Figure 2(a) shows the case where each device constituting the attack countermeasure system 1 is installed in either an external device 20 such as a server located outside the vehicle, or an on-board device 30 mounted on the vehicle. Figure 2(b) shows the case where all devices constituting the attack countermeasure system 1 are installed in the on-board device 30. In both Figure 2(a) and Figure 2(b), the second countermeasure execution device 350 is installed in the on-board device 30. The vehicle is also equipped with an electronic control system S, which is connected to the on-board device 30.

[0022] In Figure 2(a), the electronic control system S and the external device 20 are connected via a communication network using wireless communication methods such as IEEE 802.11 (Wi-Fi®), IEEE 802.16 (WiMAX®), W-CDMA (Wideband Code Division Multiple Access), HSPA (High Speed ​​Packet Access), LTE (Long Term Evolution), LTE-A (Long Term Evolution Advanced), 4G, and 5G. Alternatively, DSRC (Dedicated Short Range Communication) can be used. If the vehicle is parked in a parking lot or housed in a repair shop, a wired communication method can be used instead of a wireless communication method. For example, a LAN (Local Area Network), the internet, or a fixed telephone line can be used. In addition, the connection may be a combination of wireless and wired communication methods. For example, the connection between the electronic control system S and the base station equipment in the cellular system may be made using a wireless communication method such as 4G, and the connection between the base station equipment and the external equipment 20 may be made using a wired communication method such as a telecommunications carrier's backbone line or the internet. A gateway device may be provided at the point of contact between the backbone line and the internet.

[0023] Furthermore, in Figures 2(a) and 2(b), the in-vehicle device 30 and the electronic control system S and the ECUs that constitute the electronic control system S are connected via an in-vehicle communication network such as CAN (Controller Area Network) or LIN (Local Interconnect Network). Alternatively, they may be connected using any communication method, whether wired or wireless, such as Ethernet®, Wi-Fi®, or Bluetooth®.

[0024] In Figure 2, the in-vehicle device 30 is located outside the electronic control system S. However, the in-vehicle device 30 may also be located inside the electronic control system S, that is, as one of the components of the electronic control system S.

[0025] (2) Configuration of the electronic control system S Figure 3 shows an example of the configuration of an electronic control system S. The electronic control system S consists of multiple ECUs 10 and an in-vehicle network connecting them. Figure 3 shows eight ECUs (ECU10a to ECU10h) as an example, but naturally, the electronic control system S can be composed of any number of ECUs. In the following explanation, when describing the entire electronic control unit, one or more, we will refer to them as ECU10 or each ECU10, and when describing individual electronic control units, we will refer to them as ECU10a, ECU10b, ECU10c, ...

[0026] In the case of Figure 3, each ECU 10 is connected via an in-vehicle communication network such as CAN (Controller Area Network) or LIN (Local Interconnect Network). Alternatively, they may be connected using any communication method, whether wired or wireless, such as Ethernet®, Wi-Fi®, or Bluetooth®. Furthermore, "connection" refers to a state in which data can be exchanged, and includes not only cases where different hardware is connected via a wired or wireless communication network, but also cases where virtual ECUs (also called virtual machines) implemented on the same hardware are virtually connected to each other.

[0027] The electronic control system S shown in Figure 3 includes an integrated ECU 10a, an external communication ECU 10b, zone ECUs (10c, 10d), and individual ECUs (10e to 10h).

[0028] The integrated ECU 10a is an ECU that has the function of controlling the entire electronic control system S, as well as a gateway function that mediates communication between each ECU. The integrated ECU 10a is sometimes called a gateway ECU (G-ECU) or a mobility computer (MC). The integrated ECU 10a may also be a relay device or a gateway device.

[0029] The external communication ECU 10b is an ECU that has a communication unit for communicating with an external device 20 located outside the vehicle. The communication method used by the external communication ECU 10b is the wireless communication method or wired communication method described above. Furthermore, to implement multiple communication methods, multiple external communication ECUs 10b may be provided. Alternatively, instead of providing external communication ECUs 10b, the integrated ECU 10a may incorporate the functions of the external communication ECUs 10b.

[0030] Zone ECUs (10c, 10d) are ECUs equipped with gateway functions that are appropriately positioned according to the location and function of the individual ECUs. For example, Zone ECU 10c is an ECU that has a gateway function to mediate communication between individual ECUs 10e and 10f located at the front of the vehicle and other ECUs 10, and Zone ECU 10d is an ECU that has a gateway function to mediate communication between individual ECUs 10g and 10h located at the rear of the vehicle and other ECUs 10.

[0031] Individual ECUs (10e~10h) can be composed of ECUs with any function. Examples include drivetrain electronic control units that control the engine, steering wheel, brakes, etc., vehicle system electronic control units that control meters, power windows, etc., information system electronic control units such as navigation systems, or safety control system electronic control units that prevent collisions with obstacles or pedestrians. Furthermore, the ECUs may not be in parallel, but may be classified as master and slave units.

[0032] In the electronic control system S shown in Figure 3, each ECU 10 other than ECU 10h has a security sensor. (In the figure, this is abbreviated as SS). Thus, it is not necessary for all ECUs 10 constituting the electronic control system S to have a security sensor. Furthermore, each ECU 10 may have multiple security sensors.

[0033] (3) Configuration of ECU10 Figure 4 is a block diagram showing the configuration of ECUs (10a to 10g) equipped with security sensors. The security sensors of ECUs (10a to 10g) have a log generation unit 11 and a transmission unit 12. ECUs (10a to 10g) further have a request acquisition unit 13, a function information generation unit 14, a software storage unit 15, and a function information transmission unit 16.

[0034] The log generation unit 11 generates security logs (hereinafter referred to as "logs"). Logs are generated when the security sensor detects an anomaly and indicate the detection results of the security sensor. For example, a log is generated when an anomaly caused by a cyberattack on each ECU 10 equipped with a security sensor is detected. In other words, the timing of log generation is when the security sensor detects an anomaly. However, logs may also be generated when the security sensor detects normal operation, in addition to when an anomaly is detected.

[0035] The log generation unit 11 may further generate a liveness monitoring log indicating that the security sensor is operating. The liveness monitoring log is a security log generated to take advantage of the fact that the security sensor is operating if a log is being generated. The liveness monitoring log is sometimes called a life signal, keep-alive information, or heartbeat information. The timing of the generation of the liveness monitoring log is unrelated to the detection of anomalies in the security sensor. For example, the liveness monitoring log may be generated at regular intervals, for example, every 10 seconds or every minute. Alternatively, the liveness monitoring log may be generated at specific timings in addition to these, for example, when the vehicle ignition is turned ON. Note that the regular interval may always be constant, or it may be determined by conditions.

[0036] The transmission unit 12 transmits the log generated by the log generation unit 11 to the first attack detection device 100, which will be described later, via the in-vehicle network or via the external communication ECU 10b. If the security sensor and the first attack detection device 100 are mounted on the same ECU 10, the transmission unit 12 outputs directly to the hardware or software that implements the first attack detection device 100 without going through the in-vehicle network. The transmission unit 12 may also transmit the status monitoring log to a server device or the like located outside the vehicle.

[0037] The request acquisition unit 13 acquires a function information request from the second attack detection device 150, which will be described later. The function information request requests the transmission of function information regarding the functions of the ECU 10. The function information request may also include challenge information consisting of random numbers.

[0038] The function information generation unit 14 generates function information in response to a function information request. For example, if the function information request includes challenge information, the function information generation unit 14 reads a portion of the software stored in the software storage unit 15 and generates a hash value using the read software and the challenge information included in the function information request. The generated hash value is a hash of the software related to the function of the ECU 10, and can therefore be considered function information.

[0039] The function information transmission unit 16 transmits the hash value generated by the function information generation unit 14 as function information.

[0040] In this embodiment, the functional information is described as a hash value generated using the software and challenge information installed in the ECU10, but the functional information is not limited to this example. For example, the functional information may be a hash value generated using the data and challenge information used in the software, or it may be unhashed software or data.

[0041] 2. Configuration of each device constituting the attack countermeasure system 1 (1) Configuration of the first attack detection device 100 Referring to Figure 5, the configuration of the first attack detection device 100 will be described. The first attack detection device 100 includes a log acquisition unit 101, an attack determination table storage unit 102, an attack determination unit 103, and an attack information transmission unit 104. In this embodiment, a configuration in which the first attack detection device 100 performs attack detection processing will be described, but the processing in the first attack detection device 100 may be performed by a SOC (Security Operation Center).

[0042] The log acquisition unit 101 acquires logs generated by the security sensor from the electronic control system S. If the first attack detection device 100 is installed in the in-vehicle device 30, the log acquisition unit 101 acquires logs from the electronic control system S via the in-vehicle communication network; if it is installed in the external device 20, the log acquisition unit 101 acquires logs via wireless communication or wired communication.

[0043] The log acquisition unit 101 may also acquire logs generated by an external device 20 located outside the vehicle, in addition to or instead of logs generated by the security sensor. For example, the log acquisition unit 101 acquires logs generated by an OEM center, which is an external device 20. An attack on the vehicle may infiltrate the electronic control system S via an external device 20 such as an OEM center. In such a case, the log acquisition unit 101 acquires logs from the external device 20 that were generated when the external device 20 detected an anomaly.

[0044] The attack determination table storage unit 102 is a storage unit that stores the attack determination table used in the attack determination unit 103 for attack determination. The attack determination table is a table that shows the correspondence between the type of attack that the electronic control system S is expected to be subjected to, the predicted attack origin of the attack, the predicted attack target, the predicted attack path identified by the related ECUs which are ECUs that pass through from the predicted attack origin to the predicted attack target, and the logs that are expected to be generated by the security sensors mounted on the ECU 10 and external devices 20 when an attack occurs. The attack determination table is sometimes called a pattern matching table or a matching table. Here, the predicted attack path may include not only the ECU 10 mounted on the vehicle but also external devices 20 located outside the vehicle.

[0045] The attack determination unit 103 determines the type of cyberattack (hereinafter referred to as "attack") on the vehicle based on the logs acquired by the log acquisition unit 101. Specifically, the attack determination unit 103 determines the type of attack and attack path using an attack determination table.

[0046] Figure 6 shows an example of an attack determination table stored in the attack determination table storage unit 102. The attack determination table in Figure 6 indicates which security sensor installed in each ECU will detect an anomaly and generate a log for each type of attack (A, B, C, etc.) when an attack occurs that goes from the predicted attack origin to the predicted attack target. Since the log acquisition unit 101 acquires logs generated by security sensors, it can be said that which security sensor generates a log indicates which security sensor the log acquisition unit 101 acquired the log from. In Figure 6, 1 indicates that a log is generated by the security sensor, and 0 indicates that no log is generated.

[0047] For example, let's consider an attack of type A, where ECU10a is the starting point and ECU10e is the target, and the attack route goes through ECU10c between ECU10a and ECU10e. In this case, according to Figure 6, it is expected that logs will be generated by security sensors A and B on ECU10a and security sensor F on ECU10c. Therefore, if the log acquisition unit 101 acquires logs from security sensors A and B on ECU10a and security sensor F on ECU10c, the attack determination unit 103 can determine that the attack type of the attack received by the electronic control system S is A, and that the attack path for attack type A is ECU10a, ECU10c, and ECU10e.

[0048] Figure 6 illustrates an attack determination table when the log acquisition unit 101 acquires logs only from security sensors mounted on the ECU 10. However, when the log acquisition unit 101 acquires logs from an external device 20, the attack determination table may indicate whether or not logs are generated by the external device 20. In this case, the attack determination unit 103 can determine the attack path and attack type in which the predicted attack origin and related ECU is the external device 20.

[0049] In this embodiment, a configuration was described in which the attack determination unit 103 uses an attack determination table to determine the type of attack and the attack path of the attack received by the electronic control system S. However, the attack determination by the attack determination unit 103 may use any method.

[0050] The attack information transmission unit 104 "transmits" attack information indicating the type of attack and attack path determined by the attack determination unit 103 to the first countermeasure determination device 200 and the second attack detection device 150, which will be described later.

[0051] Here, "transmission" includes not only sending information to the in-vehicle network or external networks, but also outputting information to the internal bus. The same applies hereafter.

[0052] (2) Configuration of the first measure decision device 200 Referring to Figure 7, the configuration of the first action decision device 200 will be described. The first action decision device 200 comprises an attack information acquisition unit 201, a reference information storage unit 202, an action decision unit 203, and an instruction transmission unit 204.

[0053] The attack information acquisition unit 201 acquires attack information from the first attack detection device 100.

[0054] The standard information storage unit 202 (corresponding to the "first standard information storage unit") is a storage unit that stores standard information used in the decision-making unit 203 for determining measures. The standard information is a combination of predicted attack information, which indicates the type of attack and attack path of an attack that the vehicle is expected to be subjected to, and standard measure information (corresponding to the "first standard measure information"), which indicates measures to prevent the effects caused by an attack when the vehicle is subjected to an attack of the type of attack indicated by the predicted attack information and via the attack path indicated by the predicted attack information.

[0055] The action decision unit 203 (corresponding to the "first action decision unit") determines the action to be taken against the attack based on the attack information. Specifically, the action decision unit 203 determines the standard action information associated with the predicted attack information corresponding to the attack information acquired by the attack information acquisition unit 201 as the action to be taken by the vehicle (corresponding to the "first action"). Here, the action decided by the action decision unit 203 is an action to prevent the "effects caused by the attack". Hereinafter, the action to prevent the effects caused by the attack, which is determined by the first action decision device 200 and is taken by the first action execution device described later, will be referred to as the first action. Here, "impacts resulting from the attack" includes not only the damage caused by the attack, but also other effects besides physical harm.

[0056] First, we will describe the case in which the first action execution device 300 is mounted on a vehicle and the first action is performed on the vehicle.

[0057] One measure to prevent the effects of an attack is to prevent the attack from reaching ECUs 10 that are not located on the attack path among the ECUs 10 that make up the electronic control system S. For example, one measure is to block the in-vehicle network between ECUs 10 located on the attack path and ECUs 10 that are not located on the attack path. By blocking the connection between the attack path and ECUs 10 that are not located on the attack path, it is possible to prevent the attack from reaching ECUs 10 other than those on the attack path. Another example is to disable the function of the zone ECU 10 that functions as a gateway for the zone containing the attack path. By disabling the function of the zone ECU 10, it is possible to prevent the attack from spreading from the attacked zone to other zones.

[0058] Another example of measures to prevent the effects of an attack is to mitigate the damage caused by the attack to the ECU10 located on the attack path among the ECU10s that make up the electronic control system S. One example is to isolate the network between the ECU10 located on the attack path and the outside of the vehicle. If the firewall function of the ECU10 located on the attack path is disabled, there is a risk of unauthorized access from the outside. Therefore, by isolating the network between the ECU10 located on the attack path and the outside, it is possible to prevent damage from unauthorized access to the ECU10 located on the attack path. At this time, the network between the ECU10 not located on the attack path and the outside of the vehicle may also be isolated. Another example is to restart or initialize the ECU10 located on the attack path. By restarting or initializing the ECU10 located on the attack path and returning it to the state before the attack, it is possible to prevent damage such as malfunction of the ECU10 caused by a program that has been tampered with by the attack. Yet another example is to move logs and files stored in the memory of the ECU10 located on the attack path to the memory of an ECU10 not located on the attack path. By moving logs and files to memory that has not been attacked, it is possible to prevent damage such as unauthorized tampering of logs and files due to the attack. In these examples, ECU10, which is located in the attack path, may have already suffered damage from the attack (such as being behind a firewall or having programs and files tampered with), but the first measure can prevent further damage from occurring.

[0059] Next, we will describe the case where the first action execution device 300 is located outside the vehicle and the first action is performed outside the vehicle. One measure to prevent the effects of an attack carried out outside the vehicle is to block communication between the external device 20 located in the attack path and the electronic control system S. By blocking communication between the external device 20 located in the attack path and the electronic control system S, it is possible to prevent further attacks from progressing to the electronic control system S via the external device 20.

[0060] The measures described above are merely examples and are not limited to these examples. Furthermore, the first measure may overlap with the measures determined by the second measure determination device 250, which will be described later.

[0061] Figure 8 shows an example of reference information stored in the reference information storage unit 202. The reference information in Figure 8 associates the type of attack that the vehicle is expected to be subjected to, the attack path of the attack, and the measures to be taken if the vehicle is subjected to an attack indicated by the attack type via the attack path.

[0062] For example, in the example shown in Figure 8, attack type A, attack paths consisting of ECU10a, ECU10c, and ECU10e, and measures to block the TCU and external systems are associated. Therefore, if the attack information acquisition unit 201 acquires attack information that the attack type is A and the attack paths are ECU10a, ECU10c, and ECU10e, the action determination unit 203 determines that the measure to be taken in the vehicle is to block the TCU and external systems.

[0063] The instruction transmission unit 204 transmits instruction information (corresponding to "first instruction information") to the first action execution device 300 mounted on the vehicle, instructing it to execute the first action determined by the action decision unit 203.

[0064] The instruction transmission unit 204 may further transmit information indicating the content of the first measure decided by the measure decision unit 203 to the second measure decision device 250.

[0065] (3) Configuration of the action execution device 300 Referring to Figure 9, the configuration of the first action execution device 300 will be described. The first action execution device 300 comprises an instruction information acquisition unit 301 and an action execution unit 302.

[0066] The instruction information acquisition unit 301 (corresponding to the "first instruction information acquisition unit") acquires instruction information from the first action decision device 200.

[0067] The action execution unit 302 (corresponding to the "first action execution unit") executes a first action to prevent the effects caused by the attack, based on the instruction information acquired by the instruction information acquisition unit 301.

[0068] (4) Configuration of the second attack detection device 150 Next, the configuration of the second attack detection device 150 will be described with reference to Figure 10. The second attack detection device 150 includes an attack information acquisition unit 151, a request transmission unit 152, a function information acquisition unit 153, a reference function information storage unit 154, a damage determination unit 155, and a damage information transmission unit 156. In this embodiment, a configuration in which the second attack detection device 150 performs attack detection processing will be described, but the processing in the second attack detection device 150 may be performed by a PSIRT (Product Security Incident Response Team).

[0069] The attack information acquisition unit 151 acquires attack information from the first attack detection device 100.

[0070] The request transmission unit 152 transmits a function information request to the ECU 10 located in the attack path indicated by the acquired attack information, which is one of the ECUs 10 constituting the electronic control system S, requesting "function information". In this embodiment, the function information request includes challenge information such as random numbers.

[0071] Here, "functional information" includes data related to the software installed in the electronic control unit, as well as data output by the software installed in the electronic control unit, or converted versions of such data.

[0072] The function information acquisition unit 153 acquires function information regarding the function of the ECU 10 located in the attack path as a response to the function information request sent by the request transmission unit 152. In this embodiment, the function information is response information generated using the challenge information included in the transmitted function information request. Specifically, as an example, the response information, which is a hash value calculated using the challenge information and information regarding the function of the ECU 10, is acquired as function information.

[0073] The reference function information storage unit 154 is a storage unit that stores the function information of each ECU 10 that constitutes the electronic control system S in advance. The reference function information storage unit 154 stores the same information as the information stored in the software storage unit 15 of each ECU 10.

[0074] The damage determination unit 155 determines whether the ECU 10 is normal or not based on the functional information and determines the location of the damage in the ECU 10 located on the attack path. For example, the damage determination unit 155 determines whether the ECU 10 is normal or not by performing challenge-response authentication using the challenge information included in the functional information request and the response information, which is functional information acquired by the functional information acquisition unit 153. Specifically, the damage determination unit 155 calculates a hash value using the functional information of the ECU 10 that is pre-stored in the reference functional information storage unit 154 and the challenge information included in the transmitted functional information request. The damage determination unit 155 further compares the calculated hash value with the hash value of the functional information acquired by the functional information acquisition unit 153. If these hash values ​​are equal, the unit determines that the ECU 10 that sent the hash value is normal. Conversely, if the hash values ​​are not equal, the unit determines that the ECU 10 that sent the hash value is not normal.

[0075] Here, if the damage determination unit 155 determines that the ECU 10 that transmitted the hash value is not functioning correctly, it determines that the ECU 10 is the location of the attack. Here, if the damage determination unit 155 is the function information of a specific software installed in the ECU 10, it may determine that the software installed in the ECU 10 is the location of the attack.

[0076] In this embodiment, the request transmission unit 152 is configured to send a function information request to the ECU 10. However, the request transmission unit 152 may send the function information request to a server device located outside the vehicle, rather than to the ECU 10. For example, each ECU 10 constituting the electronic control system S may periodically send a liveness management log to a server device located outside the vehicle. Therefore, the request transmission unit 152 may send a function information request to the server device that acquires the liveness management log from the ECU 10, requesting information on the acquisition status of the liveness monitoring log. Here, the liveness monitoring log is a log that indicates whether the security sensor, which is a function of the ECU 10, is operating, and can therefore be said to be function information related to the function of the ECU 10. Therefore, the acquisition status of such a liveness monitoring log is requested as function information, and it is determined whether the ECU 10 is normal or not according to the acquisition status of the liveness monitoring log.

[0077] The damage information transmission unit 156 transmits damage information indicating the attack shown in the acquired attack information, and the location of the damage determined by the damage determination unit 155, to the second action determination device 250, which will be described later.

[0078] (5) Configuration of the second measure decision device 250 Referring to Figure 11, the configuration of the second action decision device 250 will be described. The second action decision device 250 comprises a damage information acquisition unit 251, a standard information storage unit 252, an action decision unit 253, and an instruction transmission unit 254.

[0079] The damage information acquisition unit 251 acquires damage information from the second attack detection device 150.

[0080] The standard information storage unit 252 (corresponding to the "second standard information storage unit") is a storage unit that stores standard information used in the decision-making unit 253 for determining measures. The standard information associates predicted damage information, which indicates the type of attack and predicted damage locations of attacks that the vehicle is expected to be subjected to, with standard measure information (corresponding to the "second standard measure information"), which indicates the measures to be taken at the damaged locations if damage occurs at the predicted damage locations due to an attack of the type of attack indicated by the predicted damage information.

[0081] The action decision unit 253 (corresponding to the "second action decision unit") determines the action to be taken by the vehicle based on the location of the damage indicated by the damage information. Specifically, the action decision unit 253 determines the standard action information associated with the predicted damage information corresponding to the damage information acquired by the damage information acquisition unit 251 as the action to be taken by the vehicle (corresponding to the "second action"). Here, the action decided by the action decision unit 253 is an action taken for the location of the damage. Hereinafter, the action taken for the location of the damage determined by the second action decision device 250 and executed by the second action execution device described later will be referred to as the second action.

[0082] One measure taken to address the damage is to prevent further damage to areas other than the affected location. For example, this could involve stopping the affected ECU10 or software. By stopping the affected software, it is possible to prevent other normal software that works in conjunction with that software from being affected by the attack. Another example is prohibiting access to memory from the affected location. For example, by prohibiting access to memory from the affected software, it is possible to prevent unauthorized modification of the memory.

[0083] Another example of measures taken against a damaged area is to reduce or repair the damage at that area. For example, this could involve restarting or resetting the damaged ECU10 or software. For instance, resetting the damaged software can repair the damage.

[0084] The measures described above are merely examples and are not limited to these examples. For example, measures may be taken not only on the affected area but also on the network connected to the affected area. Furthermore, the area affected by the attack (i.e., the affected area) is expected to be more limited in scope than the area where the attack may progress. Therefore, the scope of measures taken on the affected area is usually narrower than the scope of measures taken to prevent the effects caused by the attack. For example, measures to prevent the effects caused by the attack may be implemented across multiple ECUs 10, whereas measures taken on the affected area may be implemented on a specific ECU 10 or specific software or application.

[0085] Figure 12 shows an example of standard information stored in the standard information storage unit 252. The standard information in Figure 12 associates the type of attack that the vehicle is expected to be subjected to, the location of damage caused by the attack, and the measures to be taken if the location is damaged by the attack indicated by the attack type.

[0086] For example, in the example shown in Figure 12, attack type A, the damaged location which is software a of the ECU10e, and the action to stop software a are associated. Therefore, if the damage information acquisition unit 251 acquires damage information that the attack type is A and the damaged location is software a of the ECU10e, the action determination unit 253 determines that the action to be taken in the vehicle is to stop software a.

[0087] The instruction transmission unit 254 transmits instruction information (corresponding to "second instruction information") to the second action execution device 350, instructing it to carry out the action decided by the action decision unit 253.

[0088] Here, if the second action decision device 250 has obtained information from the first action decision device 200 indicating the content of the first action, the instruction transmission unit 254 may transmit instruction information that takes into account the content of the first action. For example, if the content of the first action and the second action overlap in part, the instruction transmission unit 254 may transmit instruction information to the second action execution device 350 instructing it to execute only the non-overlapping action, rather than instructing it to execute the overlapping action. Alternatively, if the first action includes an action that is not included in the second action, the instruction transmission unit 254 may transmit instruction information to the second action execution device 350 instructing it to stop that action.

[0089] (6) Configuration of the second action execution device 350 Referring to Figure 13, the configuration of the second action execution device 350 will be described. The second action execution device 350 includes an instruction information acquisition unit 351 and an action execution unit 352.

[0090] The instruction information acquisition unit 351 (corresponding to the "second instruction information acquisition unit") acquires instruction information from the second action decision device 250.

[0091] The action execution unit 352 (corresponding to the "second action execution unit") executes the second action on the damaged area based on the instruction information acquired by the instruction information acquisition unit 351.

[0092] Here, the first action decision device 200 decides on an action based on attack information acquired from the first attack detection device 100, while the second action decision device 250 decides on an action based on damage information acquired from the second attack detection device 150. Since the second attack detection device 150 determines the location of damage based on the attack information acquired from the first attack detection device 100 and transmits the damage information, the second action decision device 250 decides on an action and transmits the instruction information later than the first action decision device 200 decides on an action and transmits the instruction information. Therefore, the action execution unit 352 executes the second action after the first action execution device 300 has executed the first action.

[0093] If both the first action execution device 300 and the second action execution device 350 are mounted on the vehicle, the action execution unit 302 may "cancel" the action that was being executed based on the instruction information from the first action determination device 200 and execute the action based on the instruction information from the second action determination device 250. As a result, the action executed on the vehicle shifts from the first action to prevent the effects caused by the attack to the second action to be taken on the damaged area. Here, "lifting" includes not only lifting all of the first measures, but also lifting only a part of the first measures.

[0094] In this embodiment, a configuration has been described in which a two-stage attack detection process (first attack detection device 100, second attack detection device 150), a remediation decision process (first remediation decision device 200, second remediation decision device 250), and a remediation execution process (first remediation execution device 300, second remediation execution device 350) are performed. However, it is also possible to perform three or more stages of attack detection, remediation decision, and remediation execution. For example, when it is first detected that a vehicle has been subjected to a cyberattack, the first remediation measure (corresponding to the "third remediation measure") is to block communication between the electronic control system S and the outside of the vehicle. Next, the attack path determination process and the determination of remediation measures based on the attack path are performed in this embodiment. Finally, the damaged area determination process and the determination of remediation measures based on the damaged area are performed, thereby performing three stages of attack detection, remediation decision, and remediation execution. In this case, it is desirable that the scope in which the first remediation is performed is even wider than the scope in which the remediation measures based on the attack path are performed.

[0095] In this case, in addition to the devices shown in Figure 1, the attack countermeasure system 1 may further include a third attack detection device for detecting attacks against the vehicle, a third action determination device for determining actions to be taken when an attack against the vehicle is detected, and a third action execution device for executing those actions. For example, the third attack detection device has the same configuration as the first attack detection device 100 and includes a log acquisition unit for acquiring logs, an attack determination unit for detecting attacks against the vehicle based on the logs, and an attack information transmission unit for transmitting attack information indicating that an attack against the vehicle has been detected. The third action determination device also has the same configuration as the first action determination device 200 and includes an attack information acquisition unit for acquiring attack information from the third attack detection device, an action determination unit for determining actions to be taken over a wider range than the first action, and an instruction transmission unit for transmitting instruction information to the third action execution device to instruct it to execute those actions. The configuration of the third action execution device is the same as that of the first action execution device 300 and the second action execution device 350, and includes an instruction information acquisition unit (corresponding to the "third instruction information acquisition unit") that acquires instruction information (corresponding to the "third instruction information") from the third action decision device, and an action execution unit (corresponding to the "third action execution unit") that executes the action based on the instruction information. Alternatively, the first attack detection device 100, the first action decision device 200, and the first action execution device 300 may realize the functions of the third attack detection device, the third action decision device, and the third action execution device as described above.

[0096] 3. Operation of Attack Counter System 1 The operation of the attack countermeasure system 1 will be explained with reference to Figure 14. Figure 14 not only shows the attack countermeasure method executed by the attack countermeasure system 1, but also shows the processing procedures of programs that can be executed by each device constituting the attack countermeasure system 1. Furthermore, these processes are not limited to the order shown in Figure 14. That is, the order may be changed unless there are constraints such as a relationship where one step utilizes the result of the preceding step. The same applies to the flowchart of the embodiment described later.

[0097] The log acquisition unit 101 of the first attack detection device 100 acquires logs from the ECU 10 which constitutes the electronic control system S (S101). As described above, the log acquisition unit 101 may acquire logs from an external device 20 in addition to, or instead of, the ECU 10. The attack determination unit 103 determines the attack on the vehicle and the attack path based on the log acquired in S101 (S102). The attack information transmission unit 104 transmits attack information indicating the attack and attack path determined in S102 to the second attack detection device 150 and the first countermeasure decision device 200 (S103).

[0098] The attack information acquisition unit 201 of the first action decision device 200 acquires the attack information transmitted in S103 (S201). The action decision unit 203 determines the first action to be taken by the vehicle based on the attack information obtained in S201 (S202). Then, the instruction transmission unit 204 transmits instruction information to the action execution device 300 instructing it to execute the first action determined in S202 (S203).

[0099] The instruction acquisition unit 301 of the first action execution device 300 acquires the instruction information transmitted in S203 (S301). The action execution unit 302 executes the first action instructed by the instruction information acquired in S301 (S302).

[0100] Furthermore, the attack information acquisition unit 151 of the second attack detection device 150 acquires the attack information transmitted in S103 (S151). The request transmission unit 152 sends a function information request to the ECU 10 located on the attack path indicated by the attack information, requesting function information (S152). Then, the function information acquisition unit 153 acquires the function information transmitted from the ECU 10 as a response to the function information request (S153). The damage determination unit 155 determines whether the ECU 10 is functioning normally based on the functional information acquired in S153, and determines the location of damage in the ECU 10 located in the attack path that has been affected by the attack (S154). Then, the damage information transmission unit 156 transmits to the second action decision device 250 the attack indicated by the attack information acquired in S151, and the damage information indicating the location of the damage determined in S154 (S155).

[0101] The damage information acquisition unit 251 of the second measure decision device 250 acquires the damage information transmitted in S155 (S251). The action decision unit 253 decides on a second action to be taken by the vehicle based on the damage information acquired in S251 (S252). Then, the instruction transmission unit 254 transmits instruction information to the action execution device 350 mounted on the vehicle, instructing it to carry out the action decided in S252 (S253).

[0102] The instruction acquisition unit 351 of the second action execution device 350 acquires the instruction information transmitted in S253 (S351). The action execution unit 352 cancels the first action that was executed in S302 (S352). Then, the action execution unit 352 further executes the second action instructed by the instruction information obtained in S303 (S353).

[0103] 4.Summary As described above, according to the attack countermeasure system 1 of this embodiment, necessary measures can be taken against an attack by implementing measures determined based on the attack path to prevent the effects caused by the attack. Furthermore, after implementing measures to prevent the effects caused by the attack, appropriate measures can be implemented for the damaged area by implementing measures determined based on the damaged area to address the damaged area. Furthermore, by shifting from measures to prevent the effects of attacks that occur over a wide area of ​​the vehicle to measures targeting damage in a narrower area, the impact of measures that occur over a wide area of ​​the vehicle on the vehicle's functionality can be mitigated.

[0104] 5. Summary The features of the attack counter-systems and the like in each embodiment of the present invention have been described above.

[0105] The terms used in each embodiment are illustrative and may be replaced with synonymous terms or terms that include synonymous functions.

[0106] The block diagram used in describing the embodiment classifies and organizes the device configuration by function. Each block representing a function can be realized by any combination of hardware or software. Furthermore, since it represents a function, such a block diagram can also be understood as a disclosure of a method invention and a program invention that realizes said method.

[0107] The functional blocks that can be understood as processes, flows, and methods described in each embodiment may be reordered, unless there are constraints such as a relationship where one step utilizes the results of other preceding steps.

[0108] The terms "first," "second," through "nth" (where N is an integer) used in each embodiment and in the claims are used to distinguish between two or more configurations or methods of the same kind, and do not imply any order or hierarchy.

[0109] Furthermore, the following are examples of the configurations of the devices that constitute the attack countermeasure system of the present invention. Examples of component forms include semiconductor elements, electronic circuits, modules, and microcomputers. Examples of semi-finished products include electronic control units (ECUs) and system boards. Examples of finished products include mobile phones, smartphones, tablets, personal computers (PCs), workstations, and servers. Other devices with communication capabilities include, for example, video cameras, still cameras, and car navigation systems.

[0110] Furthermore, each device constituting the counter-attack system may be equipped with necessary functions, such as antennas and communication interfaces.

[0111] The present invention can be realized not only with dedicated hardware having the configuration and functions described in each embodiment, but also as a combination of a program for realizing the present invention recorded on a recording medium such as memory or a hard disk, and general-purpose hardware having a dedicated or general-purpose CPU and memory capable of executing this program.

[0112] Programs stored on non-transitional physical recording media of dedicated or general-purpose hardware (e.g., external storage devices (hard disks, USB memory, CD / BD, etc.) or internal storage devices (RAM, ROM, etc.)) can also be provided to the dedicated or general-purpose hardware via the recording media, or via a communication line from a server without using the recording media. This allows for the provision of the latest functions at all times through program upgrades. [Industrial applicability]

[0113] While this invention primarily focuses on systems to counter cyberattacks against automobiles, it may also focus on systems to counter cyberattacks against any other mobile object. [Explanation of Symbols]

[0114] 1 Attack Countermeasure System, 300 First Action Execution Device, 350 Second Action Execution Device, 301, 351 Instruction Information Acquisition Unit, 302, 352 Action Execution Unit

Claims

1. An attack countermeasure system (1) having a first action execution device (300) and a second action execution device (350) for executing measures against an attack on a mobile object, The first action execution device is A first instruction information acquisition unit (301) acquires first instruction information that instructs to execute a first measure, which is determined based on the attack path of the attack on the mobile body and is a measure to prevent the effects caused by the attack, The system includes a first action execution unit (302) that performs the first action based on the first instruction information, The second action execution device is A second instruction information acquisition unit (351) acquires second instruction information that instructs to carry out a second measure, which is a measure taken on the damaged area, based on the damaged area of ​​the attack, The system includes a second action execution unit (352) that executes the second action based on the second instruction information after the first action has been performed, Attack counter-system.

2. The first action execution device and the second action execution device are mounted on the mobile body. The first and second measures are performed on the mobile body. The attack counter system according to claim 1.

3. The scope of implementing the second measure is narrower than the scope of implementing the first measure. The attack counter system according to claim 2.

4. The attack countermeasure system further comprises a third action execution device, A third instruction information acquisition unit acquires third instruction information that instructs to perform a third measure when the attack on the mobile body is detected, The third measure execution device comprises a third measure execution unit that, before the first measure is executed, executes the third measure over a wider area than the first measure based on the third instruction information, The attack counter system according to claim 3.

5. The first measure is a measure to prevent the attack from reaching an electronic control device mounted on the mobile body that is not located in the attack path. The attack counter system according to claim 2.

6. The first measure described above is a measure to suppress damage to the electronic control device located in the attack path among the electronic control devices mounted on the mobile body. The attack counter system according to claim 2.

7. The second measure described above is a measure to prevent the damage from occurring in locations other than the aforementioned damaged area. The attack counter system according to claim 2.

8. The second measure is a measure to reduce or heal the damage at the damaged location. The attack counter system according to claim 2.

9. The second action execution unit cancels the first action and then executes the second action. The attack counter system according to claim 2.

10. The first action execution device is provided outside the mobile body, The first measure is performed outside the moving body. The attack counter system according to claim 1.

11. The first measure described above is an external device provided outside the mobile body, which is located in the attack path, and is a measure to block communication between the mobile body and the external device. The attack counter system according to claim 10.

12. The attack countermeasure system further includes a first action determination device (200) and a second action determination device (250) for determining measures against the attack. The first measure decision device is, An attack information acquisition unit (201) acquires attack information indicating the aforementioned attack path, A first action determination unit (203) that determines the first action based on the attack path indicated by the attack information, The system includes a first instruction transmission unit (204) that transmits first instruction information instructing the first measure to be carried out, The second measure determination device is, A damage information acquisition unit (251) acquires damage information indicating the damaged areas that were affected by the attack, A second measure determination unit (253) that determines the second measure based on the location of the damage indicated by the damage information, The system includes a second instruction transmission unit (254) that transmits a second instruction information to the second measure execution device instructing the execution of the second measure, The attack counter system according to claim 1.

13. The first measure determination device further includes a first standard information storage unit (202) that stores, in association with, predicted attack information indicating predicted attack paths of attacks that the mobile body is expected to be subjected to, and first standard measure information indicating measures to prevent the effects caused by the attack when an attack occurs via the predicted attack path. The first measure determination unit determines the measure indicated by the first standard measure information associated with the predicted attack information corresponding to the attack information as the first measure, The second measure determination device further includes a second standard information storage unit (252) that stores, in association with, predicted damage information indicating predicted damage locations of attacks that the mobile body is expected to suffer, and second standard measure information indicating measures to be taken against the predicted damage locations. The second measure determination unit determines the measure indicated by the second standard measure information associated with the predicted damage information corresponding to the damage information as the second measure. The attack counter system according to claim 12.

14. The attack countermeasure system further includes a first attack detection device (100) and a second attack detection device (150) for detecting the attack on the mobile body. The first attack detection device is A log acquisition unit (101) acquires logs generated by a security sensor in an electronic control unit mounted on the mobile body, and / or logs generated by an external device provided outside the mobile body. Based on the log, an attack determination unit (103) determines the attack path, The system includes an attack information transmission unit (104) that transmits the attack information indicating the attack path to the first countermeasure determination device and the second attack detection device, The second attack detection device is An attack information acquisition unit (151) acquires the attack information from the first attack detection device, A function information acquisition unit (153) acquires function information relating to the function of the electronic control unit located in the attack path indicated by the attack information, A damage determination unit (155) determines whether the electronic control unit is functioning normally based on the aforementioned functional information and determines the damaged location in the electronic control unit located in the attack path that has been damaged by the attack, The system includes a damage information transmission unit (156) that transmits the damage information indicating the location of the damage to the second measure determination device, The attack counter system according to claim 12.

15. The second attack detection device further includes a request transmission unit (152) that transmits a function information request to the electronic control unit located in the attack path to request the function information, The function information acquisition unit acquires the function information transmitted as a response to the function information request. The attack counter system according to claim 14.

16. The aforementioned functional information request includes challenge information, and the functional information is response information generated using the challenge information. The damage determination unit determines whether the electronic control device is functioning normally by performing challenge-response authentication using the challenge information and the response information. The attack counter system according to claim 15.

17. An attack countermeasure method performed in an attack countermeasure system (1) having a first action execution device (300) and a second action execution device (350) for performing measures against an attack on a mobile object, Based on the attack path of the attack on the mobile body, first instruction information is obtained that instructs the execution of the first measure, which is a measure to prevent the effects caused by the attack (S301), Based on the first instruction information, the first measure is executed (S302), A second measure is determined based on the damaged area affected by the attack, and a second instruction information is obtained that instructs the execution of the second measure, which is a measure taken on the damaged area (S351), After performing the first measure, the second measure is performed based on the second instruction information (S353). Methods of attack and counter-attack.

Citation Information

Patent Citations

  • On-vehicle device and incident monitoring method

    JP2019133599A